CVE-2024-20326
A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on th
Description
A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerability is due to improper authorization enforcement when specific CLI commands are used. An attacker could exploit this vulnerability by executing an affected CLI command with crafted arguments. A successful exploit could allow the attacker to read or write arbitrary files on the underlying operating system with the privileges of the root user.
Weakness: CWE-78
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco ConfD | Other Products | cna-assigner |
| Cisco | Cisco Network Services Orchestrator | Network & Security Management | cna-assigner |
Vendor-reported products (23)
- Cisco · Cisco ConfD
- Cisco · Cisco ConfD Basic
- Cisco · Cisco Network Services Orchestrator
- cisco · confd
- cisco · confd
- cisco · confd
- cisco · confd
- cisco · confd
- cisco · confd
- cisco · confd
- cisco · confd
- cisco · confd
- cisco · network_services_orchestrator
- cisco · network_services_orchestrator
- cisco · network_services_orchestrator
- cisco · network_services_orchestrator
- cisco · network_services_orchestrator
- cisco · network_services_orchestrator
- cisco · network_services_orchestrator
- cisco · network_services_orchestrator
- cisco · network_services_orchestrator
- cisco · network_services_orchestrator
- cisco · network_services_orchestrator
Vendor advisory
Cisco Crosswork Network Services Orchestrator Vulnerabilities
Cisco’s rating: High (advisory CVSS 7.8) · Published May 15, 2024
Bug IDs: CSCwi31715 , CSCwi84310
ConfD CLI Privilege Escalation and Arbitrary File Read and Write Vulnerabilities
Cisco’s rating: High (advisory CVSS 7.8) · Published May 15, 2024
Bug IDs: CSCwj67262 , CSCwj72783
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from